Impact
The vulnerability is an improper neutralization of input that allows an attacker to store malicious script within the Colibri Page Builder plugin and have it executed in the browsers of anyone who views the affected content. This stored XSS flaw is classified as CWE‑79 and compromises the integrity of the displayed page content. It can lead to the execution of arbitrary code in the context of the site, potentially enabling attacks such as defacement or further exploitation once a visitor’s browser is compromised.
Affected Systems
The issue impacts the Extend Themes Colibri Page Builder plugin for WordPress on all releases up to and including version 1.0.329. The description states that any version from an unspecified start (n/a) through 1.0.329 is affected; newer releases are not listed as impacted.
Risk and Exploitability
A CVSS score of 6.5 indicates a medium severity risk. The EPSS score is less than 1%, suggesting that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a stored XSS via the plugin’s content input fields; an attacker would need permission to submit content and exploit the flaw, and the impact is limited to the browsers of site visitors unless combined with higher‑level privileges.
OpenCVE Enrichment
EUVD